The requirements are in IC Tech Spec Chapter 7. The v1.5 and v1.5.1 change histories list no Chapter 7 changes, so the Chapter 7 wording and paragraph numbers quoted in this module come from a public v1.4 copy. Confirm critical wording against v1.5.1. ICS 705-1 sets the standard: "IDS installation, related components, and monitoring stations shall comply with Underwriters Laboratories (UL) 2050 Extent 3 standards."
Job
Requirement
Tech Spec
Protect when unoccupied
"SCIFs shall be protected by IDS when not occupied."
7.A.1.a
Cover the interior
Interior areas, including walls next to non-SCI space. The AO may accept layered controls instead.
7.A.1.b
Watch uncontrolled doors
Doors that have no access control and are not under constant observation are monitored continuously
7.A.1.c
Stand alone
"IDS's shall be separate from, and independent of, fire, smoke, radon, water, and other systems."
7.A.2.h
Rank first
When the IDS is integrated with access control, ACS notifications rank below IDS alarms
7.A.2.i
No eavesdropping
IDS components may not have audio or video capability unless the AO approves it with countermeasures
7.A.2.l
Hold the alarm
"Alarm activations shall remain displayed locally until cleared by an authorized SCI-cleared individual." Auto-reset is disabled.
7.A.2.m–n
Plan for failure
If any component fails, SCI-indoctrinated personnel occupy the SCIF or AO-approved measures apply. "IDS failure shall be addressed in the SCIF emergency plan."
7.A.1.d–e
Treat alarms as real
"Alarm activations shall be considered an unauthorized entry until resolved."
7.C.1
The AO approves the IDS plans. Acceptance testing is required before accreditation (7.A.2.o). The IDS works alongside the FF-L-2740 combination lock and the perimeter construction and never replaces either one. Access control does not replace the IDS either. See: Doors, Locks & Security Containers and See: Access Control, Identity & Hirsch.
"Installation shall comply with an Extent 3 installation as referenced in UL 2050."
IC Tech Spec 7.A.2.c (paraphrase)
Systems developed and used by the U.S. Government do not require UL certification but must comply with the Extent 3 installation requirements
UL instructions for Form CS-ASD-NISS
"The 'extent of protection' is the designation used to describe the amount of alarm protection installed to protect a particular area, room or container."
Same instructions
"Either an extent No. 3 or extent No. 5 is acceptable for use in either closed areas or alarmed rooms."
UL Form CS-ASD-NISS (closed area / alarmed room)
"3" or "5 (Prior approval is required)"
CDSE SA501 student guide
"Extent 3 requirements are the highest level of security for National Industrial Security Systems."
Extent 5. Under 32 CFR 117.15(d)(4)(ii), the CSA must give authorization on the alarm system description form for an installation that "provides a level of protection, e.g. UL's Extent 5, based on patrolling employees and CSA approval of security-in-depth." Extent 5 trades sensor coverage for patrols and layered controls. The Tech Spec has no Extent 5 option, so it never applies to a SCIF or SAPF.
Best public description of Extent 3 coverage. Before the rule lists Extent 5 as the exception, it sets this baseline: "all points of probable entry (perimeter doors and accessible windows) with magnetic contacts and motion detectors positioned in the probable intruder paths from the probable points of entry to the classified information." That sentence never says "Extent 3." Reading it as the Extent 3 description is an inference. On top of that baseline, ICD 705 requires UL 634 Level II switches and motion detection on every perimeter door, 24-hour backup power, and encrypted transmission.
These values come from the IC Tech Spec (Chapter 7 as quoted from the public v1.4 copy; Chapter 3 from v1.5.1), and they are the first numbers a reviewer looks for. Some items allow an alternative the AO approves, and any such alternative should be in writing.
#
Requirement
Value
Cite
1
UL installation level
UL 2050 Extent 3
7.A.2.b
2
Door switch
UL 634 listed HSS, Level II (new accreditations)
7.A.2.d
3
Motion sensors
UL 639 listed; HSS and motion on every perimeter door
7.A.2.d; 7.A.3.a(7)
4
Entry delay at the primary door
≤ 30 seconds
7.A.3.a(6)
5
Backup power
24 hours uninterruptible
7.B.5
6
False alarms
≤ 1 per 30 days per IDS partition
7.A.2.p
7
Response force, closed storage
15 minutes
3.H(a)
8
Response force, open storage
15 minutes with SID; 5 minutes without
3.H(b); 32 CFR 2001.43
9
SCI-indoctrinated person on site
60 minutes (UL 2050) or AO-approved time
7.C.1.c
10
Service start after a trouble signal
within 4 hours
7.C.2
11
Recurring IDS test
Semiannual
7.D.3
12
Motion walk test pass
alarm on 3 of every 4 consecutive four-step trials
7.D.3
Other numbers that come up often:
Test records, arm/disarm failure records and battery maintenance records are kept 2 years.
Networked IDS passwords are at least 12 characters and changed every six months, unless PIV/CAC authentication is used.
Duct and vent openings larger than 96 square inches need bars, grilles or baffles. IDS is not listed as a substitute.
Tech Spec 7.A.2.d requires protection with "UL 639 listed motion sensors and UL 634 listed High Security Switches (HSS) that meet UL Level II requirements." New accreditations need Level II. Existing Level I switches may stay until major IDS modifications or upgrades. UFC 4-010-05 3-4.17.3.3 adds: "Level 2 rated switches only include Balanced Magnetic Switches." That is why HSS and BMS are used interchangeably in the field.
Rule
Requirement
Cite
Perimeter doors
"SCIF perimeter doors shall be protected by an HSS and a motion detection sensor."
7.A.3.a(7)
Emergency exit doors
"Emergency exit doors shall be alarmed and monitored 24 hours per day." Egress-only doors also need a local audible annunciator.
7.A.3.a(8); 3.E.4.c
Sensor location
Inside the SCIF. Sensors outside the perimeter need AO approval and protected cabling.
7.A.3.a(1)–(2)
Failed sensor
"Failed sensors shall cause immediate and continuous alarm activation until the failure is investigated and corrected."
7.A.3.a(3)
Dual technology
Allowed if each technology reports alarms independently
7.A.3.a(4)
Quantity
Enough to meet 7.A.2.d, or as the AO approves
7.A.3.a(5)
Plenums
May be required above false ceilings or below false floors at overseas Category I and II locations. UFC: "Motion sensors are not normally required above false ceilings or below false floors."
7.A.3.a(5); UFC 3-4.17.3
HSS performance
Alarms before the non-hinged side of the door opens farther than the door's thickness
7.D.3
Cabling outside the SCIF
Encrypted line security, or ferrous conduit (EMT or rigid) with permanently sealed joints and no set screws. Service and junction boxes need GSA-approved locks.
7.A.2.e
UFC also calls for motion detection in "all Interior areas through which reasonable access to the asset could be gained." Lay out coverage so that no four-step path to the material goes undetected. Dead zones usually form behind tall cabinets, GSA containers and cubicle walls. CDSE SA501 applies the same rules to SAPFs: "All perimeter doors of your SAPF need to be protected by the IDS using HSS and motion sensors."
"PCUs shall be located within a SCIF and only SCIF personnel may initiate changes in access modes."
(1)
Arming and disarming use a device or procedure that validates the user, such as a PIN or credential
(2)
Cabling from sensors to the PCU is dedicated to the system, stays within the SCIF, and complies with electrical codes and CNSS standards
(3)
An alphanumeric display shows status continuously at the PCU and/or the monitoring station
(4)
The PCU is installed where unauthorized people cannot observe it
(5)
The PCU identifies and displays which sensors activated
(6)
Immediate, continuous annunciation of intrusion, failed sensor, tamper, maintenance mode, and shunted or masked points
(7)
Changes in power status (AC or backup) show locally and at the station
(8)
SCI-indoctrinated personnel reset events after inspecting the SCIF; auto-reset is disabled
(9)
Transmission to the monitoring station uses FIPS-certified encryption
(10)
The SCI-cleared IDS administrator changes maintenance and master profiles, PINs and passcodes from their defaults
(11)
The DoD design version is UFC 4-010-05 3-4.17.3.5: "Locate PCU within the Perimeter. Configure system to only allow cleared personnel located within the secure/protected area to initiate changes." The Fixed Facility Checklist asks two questions here: whether the PCU is inside the perimeter, and whether PCU status can be changed from outside IDS protection. A "yes" to the second question is a problem.
Co-located SCIFs that support the same IC element may share a partitioned PCU, with each partition acting as an independent control unit (7.A.2.f). The older-edition text also appears to extend this to SCIFs under a Co-Use Agreement, so confirm against v1.5.1. A Compartmented Area does not get its own partition: Tech Spec 2.C.4 states "Independent alarm systems shall not be installed in a CA." When one station monitors several systems, each system needs its own distinct audible and visible annunciation (7.A.2.g).
Coordinate with the AO's CIO. The hosting system needs an Authority to Operate under the RMF (NIST SP 800-53).
(1)
Host location
The host is restricted, logically and physically, to SCI-cleared security staff. It sits in a "Physically Protected Space": a locked room with fixed walls, floor and ceiling, Commercial Grade 1 hardware and UL 437 high-security cylinders, "protected by a UL Extent 3 burglar alarm system and access control unless manned 24 hours"
(2)(a)
Isolation
Firewalls, VPNs, virtual routing tables and application-level security. Only secure, private transfers among the PCU, host, remote terminal and station.
(2)(b)
Remote programming
If any component can be programmed remotely, the network is continuously monitored, including network intrusion detection and prevention auditing
(2)(c)
Secondary path
Optional. Used to cut down on investigations of communication failures shorter than five minutes. Supervised like the primary path. A wireless path needs AO approval after consulting the CTTA.
(2)(d)
Credentials
Unique user IDs. Passwords of at least 12 characters (letters, numbers, special characters) changed every six months, or PIV/CAC certificate authentication.
(2)(e)
Reporting
Administrators report unauthorized modifications to the AO immediately
(2)(f)
Transmission
FIPS 140-2, VPN, or closed and sealed conveyance. FIPS 197 (AES) with AO approval.
(2)(g)
Remote terminals
Role-based permissions approved by the AO. Non-SCI-cleared personnel may not modify the IDS or ACS. Separate login beyond the host login. Failed logins logged. Remote sessions documented. Hosts and PCUs patched (USG: IAVA).
(2)(h)
System variables and passwords are restricted to SCI-indoctrinated U.S. personnel (7.A.2.j). ACS events must never rank above IDS alarms (7.A.2.i).
Tech Spec v1.3 replaced the older "access/secure" terms with "arm/disarm." Many panels, forms and checklist titles still say access and secure.
Mode
Rules
Tech Spec
General
"There shall be no remote capability for changing the mode of operation by non-SCI cleared personnel." Anyone who changes the mode is SCI-indoctrinated.
7.B.1
Disarmed (access)
Authorized entry does not cause an alarm. "A record shall be maintained that identifies the person responsible for disarming the system." Tamper circuits and emergency-exit-door circuits stay armed. Some points can be armed while others are disarmed.
7.B.2
Armed (secure)
The system is armed when the last person leaves, and a record shows who armed it. Each failure to arm or disarm is reported to the facility's security officials, and those records are kept two years. Any unauthorized entry sends an alarm to the station immediately.
7.B.3
Maintenance, shunt, mask
The station is notified and logs the event. Only SCI-cleared administrators or the SSO can start maintenance mode. Shunted or masked points show at the station and reactivate at the next armed-to-disarmed transition. The SCI-cleared administrator sets the maintenance PIN. PEDs may connect for maintenance under SCI-cleared control. Remote diagnostics are logged.
7.B.4
DoD design criteria add two features that are often built into the IDS panel:
Duress (UFC 4-010-05 3-4.16): starts an alarm at the central monitoring station with "no audible or visual signal in the protected area."
Non-indoctrinated presence (UFC 3-4.15): a flashing or rotating light is approved, with controls inside the perimeter at each entrance.
When primary power fails, Tech Spec 7.B.5 requires the system to switch to emergency power automatically, without causing an alarm. "Twenty-four hours of uninterruptible backup power is required and shall be provided by batteries, an uninterruptible power supply (UPS), generators, or any combination."
Source
Requirement
Tech Spec 7.B.5
24 hours. The PCU shows the active power source. The station shows power failures and changes.
UFC 4-010-05 3-4.17.3.7
"Provide twenty-four hours of uninterruptible standby power." "When an engine-generator is available for standby power, provide batteries for IDS that provide a minimum of four hours."
DCSA SAP checklist F-44
24-hour backup power documented in the FFC
Fixed Facility Checklist, Section E
Generator hours and battery hours recorded separately
Tech Spec 7.C.2
Batteries maintained on the manufacturer's schedule; records kept two years
Battery calculation method (our method, built from the requirements above):
List the standby current of the PCU, every sensor and keypad, the communicators and encryption modules, and any network switch or PoE device in the signal path.
Use measured currents, not nameplate values. Multiply the total by 24 hours.
Add the alarm-state current multiplied by the alarm duration that the panel's listing and the applicable UL standard require. That duration is not published publicly, so confirm it.
Apply the manufacturer's temperature and aging derating, then pick the next larger battery size.
Tech Spec 7.B.6 allows these stations: a government-managed station, an AO-operated station, a Government Contractor Monitoring Station (GCMS), a national industrial monitoring station, or a cleared commercial central station.
Operators must be U.S. citizens and trained alarm monitors. They must be eligible for a U.S. SECRET clearance and trained in how the system works and operates. DCSA SAP checklist item F-43 applies the same rule to SAPFs.
The NISPOM version is 32 CFR 117.15(d)(2). It requires "SECRET-cleared central station employees" in enough numbers to monitor each alarmed area, and continuous supervision "by a U.S. citizen who has eligibility for access to SECRET information."
UL 2050 station types (from the Edition 5 NISPPAC briefing):
Type
Definition
UL category
GCMS
"A monitoring station that is operated by a defense contractor with the purpose of monitoring Industrial Security Systems." Systems must be "within 240 miles."
—
NIMS
National Industrial Monitoring Station, for systems more than 240 miles away
CRZM
Commercial UL central station
Listed central station
UUFX, CPVX or CVSU
Law-enforcement agency
Needs alarm receiving equipment; provides monitoring and dispatch
—
GCMS and NIMS compliance covers:
physical protection
alarm receiving equipment
fire protection
clocks
primary and secondary power
communication circuits
personnel
Automation systems are tied to UL 1981. Stations that use packet-switched or managed voice networks "shall utilize communication services that deliver geographically diverse signal pathways, if possible."
Tech Spec 3.H: "Response times for Intrusion Detection Systems (IDS) shall meet 32 CFR Parts 2001 and 2004."
Storage condition
Response force arrival
Then
Closed storage
15 minutes (3.H(a))
An SCI-indoctrinated person arrives within 60 minutes (UL 2050) or the time the AO approves (7.C.1.c)
Open storage with Security-in-Depth
Within 15 minutes of alarm annunciation (3.H(b))
Same
Open storage without Security-in-Depth
5 minutes (3.H(b))
Same
Security-in-Depth (SID) (Tech Spec 2.B) means layered security controls that the AO may accept. SID may change construction requirements and "extend security alarm response time to the maximum of 15 minutes." Examples from 2.B.3:
military installations, embassy compounds, and USG or contractor compounds with a dedicated response force
controlled buildings with separate building access controls, alarms and elevator controls
controlled office areas next to or around the SCIF that are protected by alarms
fenced compounds with access-controlled vehicle and/or pedestrian gates
Response procedure (7.C.1). Under a written support agreement, the response force protects the SCIF until SCI-indoctrinated personnel arrive. That person inspects the SCIF, tries to find the cause of the alarm, and resets the IDS before the response force leaves.
Fixed Facility Checklist, Section E, asks for:
who provides the initial response
whether responders are cleared
the written agreement with any external response force
the response time in minutes
whether response procedures are tested and records kept
whether the AO approved a catastrophic failure plan
Maintenance and repair personnel hold a TOP SECRET clearance or are escorted.
"Repairs shall be initiated by a service technician within 4 hours of the receipt of a trouble signal or a request for service."
Until repairs are done, SCI-indoctrinated personnel staff the SCIF 24 hours a day, unless the AO has approved documented alternate procedures.
Batteries are maintained on the manufacturer's schedule, and records are kept two years.
Network maintenance personnel inside the U.S. are U.S. persons with an escort. Outside the U.S. they hold a TS or SECRET clearance and are escorted.
Recurring testing (7.D.3): "Semi-annual IDS testing shall be conducted to ensure continued performance."
Test
Method and pass criterion
Motion
Each trial is four consecutive steps at one step per second, about 30 in ± 3 in per step, with a 3–5 second pause between trials. "An alarm shall activate at least three out of every four consecutive trials made by moving progressively through the SCIF."
HSS
The alarm activates before the non-hinged side of the door opens farther than the door's thickness
Tamper
Each equipment cover is tested for alarm in both secure and access modes
Test records list the test dates, who tested, the equipment tested, any malfunctions, and the corrective action. They are kept two years (DCSA SAP checklist F-27, citing Tech Spec 12.L.6).
False alarms (7.A.2.p): "False alarms shall not exceed one alarm per 30-day period per IDS partition." Common causes include:
HVAC diffusers blowing across PIR sensors
heaters in a sensor's field of view
microwave sensors that see through drywall into non-SCIF space
Failures to arm or disarm (reported to the security officer; the GSSO/CSSO for SAPFs)
2 years
Tech Spec 7.B.3; DCSA SAP checklist F-28
IDS test and performance records
2 years
Tech Spec 12.L.6; F-27
Battery maintenance
2 years
7.C.2
Person who armed and disarmed
"A record shall be maintained"; retention per Chapter 12
7.B.2–7.B.3
Maintenance mode, shunt and mask events
Logged by the monitoring station
7.B.4
Remote diagnostics after installation
Logged
7.B.4
Remote sessions and failed logins (networked IDS)
Logged; available to the AO
7.A.3.c(2)(h)
NISPOM alarm records: time of alarm, responder names, dispatch and arrival times, nature of the alarm, follow-up
12 months
32 CFR 117.15(d)(2)
The SCIF security officer or IDS administrator should be able to produce these on request:
arm and disarm records
failure-to-arm reports
semiannual test records
battery maintenance records
remote session logs
the IDS portion of the Fixed Facility Checklist
the response force agreement
the emergency or catastrophic failure plan
For SAPFs, DCSA checklist item F-42 also looks for the external response agreement. It should cover the response time, duties on arrival, SAPF points of contact, and how long responders stay on site.
Title and edition. UL Standards & Engagement sells the standard as UL 2050, National Industrial Security Systems. The Tech Spec uses a longer title: "…for the Protection of Classified Material." The current edition is Edition 6, published 7 April 2025 and revised 9 April 2025. Edition 5 (5 November 2010) is archived. UL 681 (Edition 15) and UL 827 (Edition 9) both reference UL 2050.
Scope as UL describes it. The standard "was developed in collaboration with U.S. federal security agencies." Its "technical requirements… describe the elements of alarm protection (intrusion detection) needed to coordinate with related security measures." A national industrial security system "is installed and is remotely monitored on alarm receiving equipment located in a government-contracted monitoring station, or an independently certified central station."
Who relies on it
How
Cite
SCIFs
Extent 3 is mandatory. Contractor SCIFs "shall maintain a current UL certificate of installation and service," and the certificate is renewed after any IDS change.
ICS 705-1; Tech Spec 7.A.2
SAPFs
UL 2050 certificate with Extent 3; USG systems are exempt from certification
DCSA SAP checklist F-30
NISPOM contractors
IDS approval may be based on ICD 705, UL 2050 or CSA standards. The alarm company must be NRTL-certified.
32 CFR 117.15(d)
Contractors on DoD installations
DCSA may accept a DoD IDS as an alternative under some conditions
ISL 2014-03
AA&E
Storage areas: Extent 2 or 3. Containers: Complete or Partial.
Form CS-ASD-NISS
UL category (CCN)
Meaning
CRZH
National Industrial Security Systems: the alarm service company that installs, services and certifies UL 2050 systems
CRZM
National Industrial Security monitoring station (NIMS)
CPVX / UUFX / CVSU
Central-station burglar alarm service / protective signaling central station / residential monitoring station
CVSG
Mercantile alarm service (UL 681), which is not UL 2050
The CRZH-listed alarm service company fills out UL Form CS-ASD-NISS (Alarm System Description) for each protected area or container.
The CSA representative signs for any item that needs prior approval. Under 32 CFR 117.15(d)(1), "CSA approval is required before installing an IDS."
The company installs and tests the system, then issues the National Industrial Security System certificate through UL. Under 117.15(d)(5), the certificate is issued to the facility through the alarm service company and is "Subject to the NRTL inspection program whereby periodic inspections are made of representative alarm installations by NRTL personnel." The response time the CSA approved "will be noted on the alarm certificate" (117.15(d)(3)).
Any change to the IDS after issue requires a renewed certificate (ICS 705-1).
What the form records:
Type of system: closed area, alarmed room, AA&E storage area, containers, GSA-approved container, or vault
Extent: closed area or alarmed room "3" or "5 (Prior approval is required)"; AA&E storage 2 or 3; containers and vaults Complete
Coverage and monitoring location
Line security: "None (Prior approval is required)", Standard, or Encrypted
Transmission method: data network requires prior approval
Investigator type
Investigator response option
Condition (UL form or instructions)
5 minutes
"applies to SAP or SCI systems"
15 minutes
"the maximum time permitted for an investigator to respond to a signal is 15 minutes"
20 or 30 minutes
Prior approval from the cognizant security office
60 minutes
Contractor representative as primary investigator (prior approval)
Not stated
A law-enforcement officer responds (prior approval)
Items that need a CSA signature: Extent 5, no line security, data-network transmission, law enforcement as monitor or investigator, and a 20- or 30-minute response.
How UL enforces the program. UL requires listed alarm companies to "successfully demonstrate compliance on an annual basis through an audit conducted by UL Solutions." Under 32 CFR 117.15(d)(5), certificates are also subject to the NRTL inspection program, in which representative installations are inspected periodically. An insurer's explainer (Hanover) says UL enters certificate reports into a database that insurers can check, and that UL spot-checks certificate holders.
Verify the company
Search UL Product iQ, which replaced UL's Online Certification Directory. It is linked from UL's Code Authority page.
Look for CRZH for the company that installs and services the system. If a NIMS monitoring station is proposed, also look for CRZM.
Write down the file number shown on the listing.
Verify the certificate. UL's public demo certificate shows which fields to check:
Field
What to confirm
File number and CCN
Matches the Product iQ listing. The CCN is the national industrial category, not mercantile (CVSG).
Issue and expiration dates
Current. The demo certificate expires one year after issue.
Protected property
The accredited space
Each system
Type of system, Extent 3, monitoring location, communication method, line security
Response time
Matches the time the CSA or AO approved
Line security
Encrypted, consistent with Tech Spec 7.A.3.b(10)
The last three rows come from Tech Spec and NISPOM requirements, not from UL's printed guidance.
UL's alarm certification program checks installations against UL 681, Installation and Classification of Burglar and Holdup Alarm Systems (Edition 15). It checks monitoring against UL 827, Central-Station Alarm Services. The CS-ASD-NISS instructions say the requirements for each national industrial extent level are "contained in UL 681." So the mercantile and national industrial programs use the same extent numbers.
Aspect
UL 681 (mercantile, bank)
UL 2050 (national industrial)
Purpose
Controlling burglary and holdup losses, often driven by insurers
Protecting classified material and AA&E as a government-required control
Who sets the extent
Insurer or customer
CSA or AO, through NISPOM, ICD 705 or DoDM 5205.07
National Industrial Security Systems (Ed. 6, 7 Apr 2025)
Installation, monitoring, service and the certificate for IDS that protects classified material; the source of Extent 3
UL 681
Installation and Classification of Burglar and Holdup Alarm Systems (Ed. 15)
Holds the extent-of-protection requirements the NISS form refers to
UL 827
Central-Station Alarm Services (Ed. 9)
How central stations are built, staffed and operated
UL 1981
Central-Station Automation Systems
Automation hardware and software at central stations, GCMS and NIMS
UL 1076
Proprietary Burglar Alarm Units and Systems
One listing path for a PCU. A UL 1076 PCU needs FIPS 140-2 certified encryption (Tech Spec 7.A.3.b(10)).
UL 1610
Central-station burglar alarm units (exact title not verified)
Another PCU listing path. A UL 1610 PCU needs FIPS 197 (AES) or FIPS 140-2.
UL 634
Exact title not verified
High security switches rated Level I or II; ICD 705 requires Level II for new accreditations
UL 639
Exact title not verified
Motion sensors: PIR, microwave, dual technology
UL 437
Exact title not verified
High-security key cylinders on the Physically Protected Space that houses a networked IDS host
UL 294
Exact title not verified
Access control units on SCIF doors; the ACS never replaces the IDS
UL 1034
Exact title not verified
Electric locking hardware. UFC requires strikes and electrified mortise locks "approved under UL 1034 for burglar resistance."
Key distinction: UL 2050 certifies an alarm service company's installation and monitoring. It does not certify products. Specify listed products (UL 1076 or UL 1610 panels, UL 634 switches, UL 639 sensors), installed and certified under a UL 2050 certificate by a CRZH-listed company.
Terminology. The DCSA open storage guide says 32 CFR Part 117 "codified requirements for open storage areas and replaced 'closed areas' as an entity." UL's CS-ASD-NISS form still says "closed area," so the industry uses both terms.
Paragraph
Requirement
117.15(d)(1)
"CSA approval is required before installing an IDS." The basis can be ICD 705, UL 2050 or CSA written standards. Installation is by "an alarm services company certified by a NRTL that meets the requirements in 29 CFR 1910.7."
(d)(2)
Allowed stations: GCMS, cleared commercial central station, cleared protective signaling service, cleared residential monitoring station, or national industrial monitoring station. Operators are SECRET-cleared. Alarm records are kept "for 12 months."
(d)(3)
If the alarm resets and no damage is seen, uncleared responders may handle it. If it does not reset and damage is seen, a cleared team is dispatched, and the CSA gets a report if the team is not on site within 1 hour. "The requirement for response is 80 percent within the time limits." For TOP SECRET, the CSA may allow up to 30 minutes when environmental factors prevent the normal time.
(d)(4)
Magnetic contacts on all points of probable entry, plus motion detectors in probable intruder paths. Lines "electronically supervised to detect evidence of tampering or malfunction." "No IDS sensors (magnetic contacts or vibration detectors) will be installed on GSA-approved security containers."
(d)(4)(i)–(v)
CSA authorization is required for: no line security (then two independent means of transmission are required); Extent 5; law enforcement as primary responder; transmission "over computer-controlled data-networks"; investigator response longer than the limits
(d)(5)
A valid, current NRTL certification for the right category of service
Storage rules (32 CFR 2001.43):
TOP SECRET open storage: IDS with a 15-minute response when SID is present, or a 5-minute response without SID.
SECRET: IDS with a 30-minute response, or inspections every 4 hours.
DCSA "will not approve the space if acceptable SID is not established unless there are onsite employees or guard services to meet the 5-minute response time required."
Current manual. DoDM 5205.07, Special Access Program Security Manual, took effect 17 January 2025. It is a combined manual that "incorporates and cancels" Volume 3 (Physical Security, 23 April 2015). Physical security is now Section 15, "Physical Security Procedures." The SAPF-AO "is responsible for reviewing and approving or disapproving physical security preconstruction plans for, and physically inspecting and accrediting, reaccrediting, and de-accrediting, a SAPF."
In practice, SAPF IDS follows Tech Spec Chapter 7. DCSA's January 2026 SAP compliance checklist (v2) cites Chapter 7 paragraphs throughout:
Item
Requirement
Tech Spec
F-26
SAPF protected by IDS and tested semiannually
7.A.1.a; 7.D.3.b
F-27
Test records kept 2 years
12.L.6
F-28
Each failure to arm or disarm reported to the GSSO/CSSO; records kept 2 years
7.B.3.c
F-29
Entrance delay ≤ 30 seconds
7.A.3.a.6
F-30
"Does the SAPF IDS have a (UL) 2050 Standard certificate with Extent 3 installation for IDS components and monitoring stations?"
7.A.2.a–c
F-32
U.S. companies using U.S. citizens
7.D.1
F-41
Closed storage: 15 min. Open storage: 15 min with SID, 5 min without.
3.H
F-42
External response agreement: response time, duties, points of contact, time on site
12.L.2
F-43
Station supervised by trained U.S. citizens eligible for SECRET
7.B.6.b
F-44
24 hours of uninterruptible backup power, documented in the FFC
7.B.5.b
CDSE SA501 (Nov 2024): "SAPF construction requirements require the use of UL Level II HSS. In existing facilities, the use of existing UL Level I HSS are authorized until major IDS modifications or upgrades are made."
Panel to station: transmission uses NIST FIPS-certified encryption. A UL 1610 listed PCU needs FIPS 197 (AES) or FIPS 140-2. A UL 1076 listed PCU needs FIPS 140-2. Any other method needs AO approval, noted on the certification (7.A.3.b(10)).
LAN/WAN: FIPS 140-2, VPN, or closed and sealed conveyance. FIPS 197 is allowed with AO approval (7.A.3.c(2)(g)).
Secondary paths: supervised like the primary. A wireless or cellular secondary path needs AO approval after consulting the CTTA (7.A.3.c(2)(d)).
NISPOM: "None" for line security needs CSA approval plus two independent transmission paths. Data-network transmission needs CSA acceptance criteria (117.15(d)(4)(i), (iv)).
Algorithm vs. module. FIPS 197 is the AES algorithm standard. FIPS 140-2 and 140-3 validate cryptographic modules. The Tech Spec mixes the two, so ask the vendor for the CMVP module certificate, not just the word "AES."
The 2026 transition. NIST's CMVP stopped accepting FIPS 140-2 submissions on 1 April 2022. FIPS 140-2 validations move to the Historical List on 21 September 2026; the NIST schedule table also shows 22 September 2026. NIST says: "Even on the historical list, CMVP supports the purchase and use of these modules for existing systems."
Supervision interval. Older DCSA guidance polled every six minutes. The Tech Spec mentions "communication failures less than five minutes" when explaining secondary paths. Confirm the interval your AO or CSA expects.
Perimeter door has an HSS but no motion coverage, or motion but only a standard contact
7.A.3.a(7)
2
Level I or non-UL 634 switch on a new accreditation
7.A.2.d
3
PCU or keypad outside the SCIF, or arm state can be changed from outside
7.A.3.b(1); FFC Sec. E
4
Sensor cable above a corridor ceiling with no encryption or sealed ferrous conduit; set-screw EMT fittings
7.A.2.e
5
Entry delay over 30 seconds; auto-reset left on
7.A.3.a(6); 7.A.2.m
6
Installer or master codes left at factory defaults
7.A.3.b(11)
7
Batteries last less than 24 hours, or no calculation in the FFC
7.B.5; F-44
8
Communicator not FIPS-certified, or data path not approved
7.A.3.b(10); 117.15(d)(4)(iv)
9
IDS shares a panel with fire or water systems
7.A.2.h
10
Video-verified motion sensors, or devices with microphones, without AO approval
7.A.2.l
11
Walk test not done with the four-step, 3-of-4 method
7.D.3
12
Certificate missing, expired, mercantile, not Extent 3, or not renewed after changes
7.A.2.a–b; ICS 705-1
BMS alignment. Mount the switch on the secure side and keep it within the manufacturer's gap tolerance. Door sag, weather-strip compression and acoustic gaskets shift the gap over time.
Motion above ceilings and below raised floors. UFC says this is not normally required. It may be required at overseas Category I and II sites, or when the AO decides. Expect the AO to require plenum motion or another fix in two cases: the perimeter wall stops at the drop ceiling instead of the true deck, or a raised-floor plenum connects to non-SCIF space. Settle this on the pre-construction checklist.
Ducts. Openings larger than 96 square inches need bars, grilles or metal baffles, unless one dimension is under 6 inches (3.G.7.c). IDS is not listed as a substitute, so do not design in-duct motion as the fix without written AO approval. See: Penetrations, Utilities & Life Safety.
Listing. Confirm the company is listed as CRZH in UL Product iQ, and CRZM for a NIMS station. Write down the file number.
Track record. Ask for a redacted sample UL 2050 certificate and a description of the company's CS-ASD-NISS process. Confirm it has done Extent 3 closed-area work and SCIF or SAPF accreditations.
Monitoring. Confirm the station type (GCMS, NIMS or UL central station) and that operators are U.S. citizens eligible for SECRET. If the AO requires a 5-minute response, confirm who provides the on-site response.
Clearances and contracts. Monitoring by a cleared commercial station involves government sponsorship, typically a DD Form 254, and clearance processing that UL does not control.
People. A U.S. company using U.S. citizens for installation and testing (7.D.1). Maintenance technicians TOP SECRET-cleared or escorted (7.C.2). The DISA Traditional Security Checklist also checks "IDS Installation and Maintenance Personnel - Suitability Checks."
Service. Put service start within 4 hours of a trouble signal (7.C.2) in the contract.
Encryption. Ask for the communicator make, model and CMVP certificate, and check its FIPS 140-3 status.
Sequencing. Get CSA or AO approval before installation (117.15(d)(1); 7.A.2.o). Practitioners trace accreditation failures to "design decisions made without reference to ICD 705… and documentation gaps that emerge too late to fix."
Red flag
Why it matters
Offers a mercantile certificate
Not a UL 2050 certificate
Proposes Extent 5 for a SCIF or SAPF
Not allowed under ICD 705
Wants remote programming with no network monitoring plan
7.A.3.c(2)(c)
Cannot name the monitoring station or say whether its operators are eligible for SECRET